EP0328062B1 - Carte à puce à tolérance de défauts - Google Patents
Carte à puce à tolérance de défauts Download PDFInfo
- Publication number
- EP0328062B1 EP0328062B1 EP89102139A EP89102139A EP0328062B1 EP 0328062 B1 EP0328062 B1 EP 0328062B1 EP 89102139 A EP89102139 A EP 89102139A EP 89102139 A EP89102139 A EP 89102139A EP 0328062 B1 EP0328062 B1 EP 0328062B1
- Authority
- EP
- European Patent Office
- Prior art keywords
- microcontroller
- smart card
- fault tolerant
- tolerant smart
- memory
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Lifetime
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/16—Error detection or correction of the data by redundancy in hardware
- G06F11/1629—Error detection by comparing the output of redundant processing systems
- G06F11/1654—Error detection by comparing the output of redundant processing systems where the output of only one of the redundant processing components can drive the attached hardware, e.g. memory or I/O
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/0703—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
- G06F11/0706—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation the processing taking place on a specific hardware platform or in a specific software environment
- G06F11/073—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation the processing taking place on a specific hardware platform or in a specific software environment in a memory management context, e.g. virtual memory or cache management
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/0703—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
- G06F11/079—Root cause analysis, i.e. error or fault diagnosis
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/16—Error detection or correction of the data by redundancy in hardware
- G06F11/1629—Error detection by comparing the output of redundant processing systems
- G06F11/1641—Error detection by comparing the output of redundant processing systems where the comparison is not performed by the redundant processing components
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/16—Error detection or correction of the data by redundancy in hardware
- G06F11/1629—Error detection by comparing the output of redundant processing systems
- G06F11/165—Error detection by comparing the output of redundant processing systems with continued operation after detection of the error
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/22—Detection or location of defective computer hardware by testing during standby operation or during idle time, e.g. start-up testing
- G06F11/2205—Detection or location of defective computer hardware by testing during standby operation or during idle time, e.g. start-up testing using arrangements specific to the hardware being tested
- G06F11/2236—Detection or location of defective computer hardware by testing during standby operation or during idle time, e.g. start-up testing using arrangements specific to the hardware being tested to test CPU or processors
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06K—GRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
- G06K19/00—Record carriers for use with machines and with at least a part designed to carry digital markings
- G06K19/06—Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
- G06K19/067—Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components
- G06K19/07—Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips
- G06K19/072—Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips the record carrier comprising a plurality of integrated circuit chips
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06K—GRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
- G06K19/00—Record carriers for use with machines and with at least a part designed to carry digital markings
- G06K19/06—Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
- G06K19/067—Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components
- G06K19/07—Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips
- G06K19/073—Special arrangements for circuits, e.g. for protecting identification code in memory
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/341—Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00016—Relations between apparatus, e.g. franking machine at customer or apparatus at post office, in a franking system
- G07B17/0008—Communication details outside or between apparatus
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00185—Details internally of apparatus in a franking system, e.g. franking machine at customer or apparatus at post office
- G07B17/00314—Communication within apparatus, personal computer [PC] system, or server, e.g. between printhead and central unit in a franking machine
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/0806—Details of the card
- G07F7/0813—Specific details related to card security
- G07F7/082—Features insuring the integrity of the data on or in the card
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/0806—Details of the card
- G07F7/0833—Card having specific functional components
- G07F7/084—Additional components relating to data transfer and storing, e.g. error detection, self-diagnosis
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1008—Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/08—Error detection or correction by redundancy in data representation, e.g. by using checking codes
- G06F11/10—Adding special bits or symbols to the coded information, e.g. parity check, casting out 9's or 11's
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00016—Relations between apparatus, e.g. franking machine at customer or apparatus at post office, in a franking system
- G07B17/0008—Communication details outside or between apparatus
- G07B2017/00153—Communication details outside or between apparatus for sending information
- G07B2017/00177—Communication details outside or between apparatus for sending information from a portable device, e.g. a card or a PCMCIA
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00185—Details internally of apparatus in a franking system, e.g. franking machine at customer or apparatus at post office
- G07B17/00314—Communication within apparatus, personal computer [PC] system, or server, e.g. between printhead and central unit in a franking machine
- G07B2017/00338—Error detection or handling
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00185—Details internally of apparatus in a franking system, e.g. franking machine at customer or apparatus at post office
- G07B17/00314—Communication within apparatus, personal computer [PC] system, or server, e.g. between printhead and central unit in a franking machine
- G07B2017/00346—Power handling, e.g. power-down routine
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00733—Cryptography or similar special procedures in a franking system
- G07B2017/0079—Time-dependency
Definitions
- the present invention relates to a fault tolerant smart card and, more specifically, to a fault tolerant smart card which may find particular application in the postage meter industry.
- Postage meter smart cards are known from GB-A-2 185 443, for example.
- Integrated circuit or so-called “intelligent” or “smart” cards which include a microprocessor and memory are commercially available and are useful in many applications.
- smart cards To securely transport monetary funds, including transportation of postal funds or information relating to postage funds. See , for example, US-A-4 980 542 entitled “Postal Charge Accounting System” (EP-A-0 328 059) wherein departmental postage meter use information is stored in smart card memory, and US-A-4 978 839 entitled “Postage Meter Value Card System” (EP-A-0 328 057) wherein postage meter funds are transferred from a value card center to a postage meter for recharging the postage meter vault.
- EP-A-0 147 599 generally discloses a data processing system including a main processor and a co-processor and co-processor error handling logic.
- a fault tolerant smart card having primary functional units including a standard ISO interface, a primary microcontroller, main memory including ROM, RAM and EEPROM, a clock generator and a power source.
- the primary microcontroller addresses an access account register and a microcontroller fault detector which, in turn, addresses an exception register.
- Secondary smart card functional units are provided including a secondary microcontroller, secondary memory which may include ROM and associated check bits, a funds remaining shadow register, the access account register, the microcontroller fault detector, and the exception condition register.
- a private access port is also provided. All of the secondary units requiring power support are connected to an alternate battery power source.
- the secondary microcontroller is connected to the primary and secondary clock units, the microcontroller fault detector and the funds remaining register.
- the secondary microcontroller addresses the secondary memory and has read-only access to the main memory.
- the primary and secondary microcontrollers operate synchronously and execute in parallel identical instructions from the same memory store, but with the secondary microcontroller having read-only access to the main memory.
- the microcontroller fault detector senses a fault in either of the main or secondary microcontrollers, as evidenced by an inconsistency between microcontroller signals, the exception register will be written into. When this occurs the primary microcontroller will be maintained in a frozen state and the secondary microcontroller will be released from the main memory to address the secondary memory and run known test patterns. Should a fault occur during the test the secondary microcontroller is assumed to be faulty and the main microcontroller will be permitted to continue processing. Of course, the user might be notified that card service and/or replacement is required.
- the private access port permits service personnel to directly access the secondary microcontroller, the funds remaining register, the access account register and the exception condition register. Service personnel might also make use of the secondary microcontroller, such as to access in read-only fashion the main memory. In the preferred embodiment including check bits the check bits would detect and circumvent any single bit failure in the secondary memory.
- the fault tolerant smart card according to the present invention advantageously provides a smart card capable of detecting and circumventing a single bit or single path failure. Notwithstanding such a failure, the fault tolerant smart card remarkably provides "back-door" access through a private access port to important information held in the smart card.
- the person acquiring access through the private access port is able to determine the amount of any funds remaining in the card and access other important information in the card main memory.
- the primary functional units communicate via the standard ISO interface in a traditional manner. Therefore, the fault tolerant smart card in accordance with the invention may be used in conjunction with existing, unmodified equipment.
- the fault tolerant smart card according to the present invention may find particular application in the systems disclosed in the aforementioned patent applications.
- smart card 10 includes a set of primary functional units including a standard ISO type interface 12, a microcontroller unit 14, addressable read-only memory (ROM) 16, random access memory (RAM) 18, electronically erasable programmable read-only memory (EEPROM) 20, primary and secondary clock generators 22, 26, respectively, and a primary power source 24.
- ROM read-only memory
- RAM random access memory
- EEPROM electronically erasable programmable read-only memory
- primary and secondary clock generators 22, 26, respectively and a primary power source 24.
- the preferred General Electric smart card referred to in the aforementioned patent applications derives power through the ISO interface, as shown, but an external primary power supply is not critical to the present invention.
- the foregoing elements, interconnected as shown, comprise the primary functional units for carrying out normal operation of the smart card.
- secondary functional units are provided for fault tolerant card support.
- the secondary units include a second clock generator 26 connected to an alternate battery power source 28 and to both microcontrollers 14, 30.
- the secondary microcontroller is connected to secondary memory 32, a microcontroller fault detector 36, and a funds remaining shadow register 38.
- check bits 34 are provided in association with secondary memory 32 to monitor single bit failures within the secondary memory.
- the secondary microcontroller is connected in an addressable manner to ROM 32 and to funds remaining register 38.
- Secondary microcontroller 30 is also connected to a private access port 44 and has read-only access to main memory 20. Secondary microcontroller 30 is supported by primary power source 24 and alternate battery source 28.
- An access account register 40 and an exception condition register 42 addressed by the microcontroller fault detector are also provided.
- Each of funds remaining register 38, access account register 40, and exception condition register 42 are also connected to private access port 44 and are supported by battery source 28.
- Secondary memory 32 is also supported by battery source 28 and is connected to exception condition register 42.
- Access account register 40 is addressed by primary microcontroller 14 and is written into after each card use to maintain a history trace of the identity of the user, the memory address accessed, and the information stored at that address.
- the present smart card circuit provides detection and circumvention of single bit and single path smart card faults.
- both microcontrollers 14, 30 work in a synchronous mode of operation to execute in parallel identical instructions from the same memory store.
- secondary microcontroller 30 updates funds remaining register 38 to provide a running summary of the funds that remain stored in the card.
- microcontroller fault detector here shown as exclusive "OR" gate 36
- exclusive "OR" gate 36 would trigger a high output signal, thereby writing into exception condition register 42. If the exception register 42 is written into, program information in secondary memory 32 will direct secondary microcontroller 30 to release main memory 16, 18, 20 and run known test patterns stored in secondary memory 32. During this time main microcontroller 14 remains in a frozen state. Should a fault occur during the test, secondary processor 30 is assumed to be faulty and main processor 14 is permitted to continue processing. However, if no faults are found during the known test pattern, the main processor 14 is assumed to be faulty and the user is notified of a fault condition.
- secondary memory 32 is preferably provided with associated check bits, sometimes referred to as "Hemming Bits", to circumvent any bit failures within secondary memory 32.
- the fault tolerant smart card substantially eliminates the risk that funds and/or accounting information stored in the card will be lost due to card failure. Indeed, should a card failure occur, service personnel may simply access the remaining funds amount and other information held in main memory and transfer this information to a new smart card or other recording medium. In this manner the customer is assured that monetary funds and information will not be compromised due to a smart card malfunction. As will be readily appreciated, this capability will avoid the deleterious effects to customer relations that might otherwise result from such card failures.
- the fault tolerant smart card advantageously detects smart card failures and, notwithstanding such a failure, permits private access to important information stored in the faulty card.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Quality & Reliability (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Computer Security & Cryptography (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Computer Networks & Wireless Communication (AREA)
- Health & Medical Sciences (AREA)
- Biomedical Technology (AREA)
- Techniques For Improving Reliability Of Storages (AREA)
- Test And Diagnosis Of Digital Computers (AREA)
- Devices For Checking Fares Or Tickets At Control Points (AREA)
- Credit Cards Or The Like (AREA)
Claims (22)
- Carte à microprocesseur insensible aux défaillances (10) comprènant :
une interface entrée-sortie standard (12);
des moyens d'horloge (22, 26) pour fournir une référence de temps lors des opérations de la carte à microprocesseur;
des moyens de mémoire principale (16, 18, 20) pour stocker un programme et des informations;
un premier moyen de microcontrôleur (14) relié à ladite interface (12), auxdits moyens d'horloge (22, 26) et auxdits moyens de mémoire principale (16, 18, 20) pour exécuter les fonctions normales de la carte à microprocesseur;
un moyen de microcontrôleur secondaire (30) connecté audit premier moyen de microcontrôleur (14), auxdits moyens d'horloge (22, 26), auxdits moyens de mémoire principale (16, 18, 20) et à un moyen de mémoire secondaire (32) pour exécuter les fonctions normales de la carte à microprocesseur en synchronisme avec ledit premier moyen de microcontrôleur (14);
un moyen (36) de détection d'erreur de microcontrôleur relié audit premier moyen de microcontrôleur (14) et audit moyen de microcontrôleur secondaire (30) afin de détecter une défaillance de l'un ou l'autre dudit premier microcontrôleur ou dudit microcontrôleur secondaire (14, 30); et
un moyen d'alimentation primaire (24) relié audit premier moyen de microcontrôleur (14). - Carte à microprocesseur insensible aux défaillances (10) selon la revendication 1, dans laquelle ledit moyen de microcontrôleur secondaire (30) a une consultation seule desdits moyens de mémoire principale (16, 18, 20).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 1, dans laquelle lesdits moyens d'horloge (22, 26) comprennent en outre une horloge primaire (22) et une horloge secondaire (26), ladite horloge secondaire (26) étant reliée à un moyen d'alimentation auxiliaire à batterie (28).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 1, comprenant en outre un registre des comptages d'accès (40) relié audit premier moyen de microcontrôleur (14) et adressé par celui-ci pour fournir une trace historique de l'identité de l'utilisateur et des emplacements en mémoire adressés par des utilisateurs antérieurs.
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 1, dans laquelle ladite mémoire secondaire (32) comprend en outre une mémoire morte (32) comportant une programmation pour le passage d'une ou de plusieurs configurations de test connues sur ledit second microcontrôleur (30).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 5, dans laquelle ladite programmation de la mémoire secondaire est activée par ledit moyen (36) de détection d'erreurs de microcontrôleur lors de la détection d'une défaillance de l'un ou l'autre desdits premier ou second moyens de microcontrôleur (14, 30).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 6, dans laquelle, lors de l'indication de la défaillance d'un microcontrôleur par ledit moyen (36) de détection d'erreurs de microcontrôleur, ledit premier microcontrôleur (14) est maintenu à l'état gelé alors que ledit microcontrôleur secondaire (30) fait passer lesdites configurations de test connues.
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 7, dans laquelle, dans le cas où il se produit une erreur dans lesdites configurations de test connues, ledit microcontrôleur secondaire (30) est supposé en défaut et ledit premier microcontrôleur (14) peut continuer le traitement.
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 7, dans laquelle, dans le cas où il ne se produit pas une erreur dans lesdites configurations de test connues, ledit premier microcontrôleur (14) est supposé en défaut et la défaillance de la carte est indiquée à l'utilisateur.
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 9, comportant en outre un moyen de point d'accès privé (44) relié audit second moyen de microcontrôleur (30) pour permettre l'accès d'un service à la carte à microprocesseur insensible aux défaillances (10).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 10, comprenant en outre un registre des fonds restants (38) relié audit second microcontrôleur (30) et relié en outre audit moyen de point d'accès privé (44) et accessible par l'intermédiaire de ce dernier afin d'indiquer la quantité restante des fonds stockés dans la carte à microprocesseur insensible aux défaillances (10).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 10, comprenant en outre un moyen de comptage d'accès (40) relié audit premier moyen de microcontrôleur (14) et relié audit moyen de point d'accès privé (44) et accessible par l'intermédiaire de ce dernier afin de fournir une trace de l'histoire des emplacements en mémoire des identités des utilisateurs adressés par des utilisateurs antérieurs.
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 11, dans laquelle ledit microcontrôleur secondaire (30), ladite mémoire secondaire (32), et ledit registre des fonds restants (38) sont reliés à une source d'alimentation auxiliaire à batterie (28).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 12, dans laquelle ledit microcontrôleur secondaire (30), ladite mémoire secondaire (32) et ledit moyen de comptage des accès (40) sont reliés à une source d'alimentation auxiliaire à batterie (28).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 10, comprenant en outre un moyen de bit de contrôle (34) associé à ladite mémoire secondaire (32) pour détecter et circonvenir les défaillances d'un simple bit ou d'un simple trajet à l'intérieur de ladite mémoire secondaire (32).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 1, dans laquelle ledit moyen de détection d'erreur de microcontrôleur (36) comprend en outre une porte "OU" Exclusif (36) recevant avec le signal de sortie de chacun desdits premier et second microcontrôleurs (14, 30), ladite porte "OU" Exclusif (36) étant déclenchée afin de produire un signal d'erreur dans le cas où il se produirait une contradiction entre les signaux de sortie desdits microcontrôleurs.
- Carte à microprocesseur insensible aux défaillances (10) comportant :
une interface entrée-sortie standard (12);
des moyens d'horloge (22, 26) pour fournir une référence de temps pendant les opérations de la carte à microprocesseur;
des moyens de mémoire principale (16, 18, 20) pour stocker un programme et des informations;
un premier moyen de microcontrôleur (14) relié à ladite interface (12), auxdits moyens d'horloge (22, 26) et auxdits moyens de mémoire principale (16, 18, 20) pour exécuter les fonctions normales de la carte à microprocesseur;
un moyen de microcontrôleur secondaire (30) relié audit premier moyen de microcontrôleur (14), audit moyen d'horloge (22, 26), auxdits moyens de mémoire principale (16, 18, 20) et à un moyen de mémoire secondaire (32), ledit moyen de microcontrôleur secondaire (30) exécutant les fonctions normales de la carte à microprocesseur en synchronisme avec ledit premier moyen de microcontrôleur (14);
un moyen de détection d'erreur de microcontrôleur (36) relié auxdits premier moyen de microcontrôleur et moyen de microcontrôleur secondaire (14, 30) pour détecter une contradiction entre lesdits premier moyen de microcontrôleur et moyen de microcontrôleur secondaire (14, 30); et
un moyen de point d'accès privé (44) relié audit microcontrôleur secondaire (30) pour fournir un accès privé à la carte à microprocesseur insensible aux défaillances (10). - Carte à microprocesseur insensible aux défaillances (10) selon la revendication 17, dans laquelle, lors de la détection d'une erreur par ledit moyen de détection d'erreur de microcontrôleur (36), ledit premier microcontrôleur (14) est maintenu à l'état gelé et ledit microcontrôleur secondaire (30) est libéré desdits moyens de mémoire principale (16, 18, 20) pour faire passer des configurations de test connues sous la direction dudit moyen de mémoire secondaire (32).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 18, dans laquelle, dans le cas où il se produit une erreur pendant lesdites configurations de test connues, ledit microcontrôleur secondaire (30) sera supposé fautif et ledit premier microcontrôleur (14) sera autorisé à poursuivre le traitement.
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 18, dans laquelle, dans le cas où il ne se produit aucune erreur pendant lesdites configurations de test connues, ledit premier microcontrôleur (14) est supposé en défaut et un signal de carte défaillante est transmis à l'utilisateur.
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 20, dans lequel ledit point d'accès privé (44) permet l'accès à une information contenue dans lesdits moyens de mémoire principale (16, 18, 20).
- Carte à microprocesseur insensible aux défaillances (10) selon la revendication 21, comprenant en outre un registre des fonds restants (38) relié audit microcontrôleur secondaire (30) et audit moyen de point d'accès privé (44) pour stocker une information concernant les fonds disponibles qui restent dans la carte à microprocesseur insensible aux défaillances (10).
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US07/153,391 US4908502A (en) | 1988-02-08 | 1988-02-08 | Fault tolerant smart card |
US153391 | 1988-02-08 |
Publications (3)
Publication Number | Publication Date |
---|---|
EP0328062A2 EP0328062A2 (fr) | 1989-08-16 |
EP0328062A3 EP0328062A3 (fr) | 1991-09-18 |
EP0328062B1 true EP0328062B1 (fr) | 1994-04-20 |
Family
ID=22547024
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
EP89102139A Expired - Lifetime EP0328062B1 (fr) | 1988-02-08 | 1989-02-08 | Carte à puce à tolérance de défauts |
Country Status (9)
Country | Link |
---|---|
US (1) | US4908502A (fr) |
EP (1) | EP0328062B1 (fr) |
JP (1) | JP2922211B2 (fr) |
AU (1) | AU616936B2 (fr) |
CA (1) | CA1315408C (fr) |
CH (1) | CH679434A5 (fr) |
DE (1) | DE68914696T2 (fr) |
FR (1) | FR2626991B1 (fr) |
GB (1) | GB2215888B (fr) |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US8055936B2 (en) | 2008-12-31 | 2011-11-08 | Pitney Bowes Inc. | System and method for data recovery in a disabled integrated circuit |
US8060453B2 (en) | 2008-12-31 | 2011-11-15 | Pitney Bowes Inc. | System and method for funds recovery from an integrated postal security device |
Families Citing this family (30)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP3028815B2 (ja) * | 1988-08-19 | 2000-04-04 | 株式会社東芝 | 携帯可能電子装置の伝送方法と携帯可能電子装置 |
JPH03171384A (ja) * | 1989-11-30 | 1991-07-24 | Sony Corp | 情報読取装置 |
USRE42773E1 (en) | 1992-06-17 | 2011-10-04 | Round Rock Research, Llc | Method of manufacturing an enclosed transceiver |
US5776278A (en) | 1992-06-17 | 1998-07-07 | Micron Communications, Inc. | Method of manufacturing an enclosed transceiver |
US7158031B2 (en) * | 1992-08-12 | 2007-01-02 | Micron Technology, Inc. | Thin, flexible, RFID label and system for use |
AT400774B (de) * | 1992-12-31 | 1996-03-25 | Skidata Gmbh | Datenträger |
US5473145A (en) * | 1992-10-22 | 1995-12-05 | Skidata Computer Gesellschaft M.B.H. | Data carrier |
US5884292A (en) * | 1993-05-06 | 1999-03-16 | Pitney Bowes Inc. | System for smart card funds refill |
US5557516A (en) * | 1994-02-04 | 1996-09-17 | Mastercard International | System and method for conducting cashless transactions |
US5489014A (en) * | 1994-08-03 | 1996-02-06 | Journomat Ag | Apparatus for checking coins and reading cards in an article vending machine |
US6012634A (en) * | 1995-03-06 | 2000-01-11 | Motorola, Inc. | Dual card and method therefor |
US6151590A (en) * | 1995-12-19 | 2000-11-21 | Pitney Bowes Inc. | Network open metering system |
US6157919A (en) | 1995-12-19 | 2000-12-05 | Pitney Bowes Inc. | PC-based open metering system and method |
US5704046A (en) * | 1996-05-30 | 1997-12-30 | Mastercard International Inc. | System and method for conducting cashless transactions |
US5898785A (en) * | 1996-09-30 | 1999-04-27 | Pitney Bowes Inc. | Modular mailing system |
US5988510A (en) * | 1997-02-13 | 1999-11-23 | Micron Communications, Inc. | Tamper resistant smart card and method of protecting data in a smart card |
FR2761802B1 (fr) | 1997-04-08 | 1999-06-18 | Sgs Thomson Microelectronics | Ensemble de deux memoires sur un meme circuit integre monolithique |
US5963928A (en) * | 1997-07-17 | 1999-10-05 | Pitney Bowes Inc. | Secure metering vault having LED output for recovery of postal funds |
US6339385B1 (en) | 1997-08-20 | 2002-01-15 | Micron Technology, Inc. | Electronic communication devices, methods of forming electrical communication devices, and communication methods |
US6109530A (en) * | 1998-07-08 | 2000-08-29 | Motorola, Inc. | Integrated circuit carrier package with battery coin cell |
DE19928733A1 (de) * | 1999-06-23 | 2001-01-04 | Giesecke & Devrient Gmbh | Halbleiterspeicher-Chipmodul |
US6273339B1 (en) | 1999-08-30 | 2001-08-14 | Micron Technology, Inc. | Tamper resistant smart card and method of protecting data in a smart card |
US6284406B1 (en) | 2000-06-09 | 2001-09-04 | Ntk Powerdex, Inc. | IC card with thin battery |
DE20020635U1 (de) | 2000-11-28 | 2001-03-15 | Francotyp-Postalia AG & Co., 16547 Birkenwerder | Anordnung zur Stromversorgung für einen Sicherheitsbereich eines Gerätes |
EP1514166B1 (fr) * | 2003-04-15 | 2012-01-11 | NDS Limited | Horloge securisee |
CN1315054C (zh) * | 2003-12-24 | 2007-05-09 | 上海华虹集成电路有限责任公司 | 一种智能卡仿真卡 |
FR2869430A1 (fr) * | 2004-04-27 | 2005-10-28 | St Microelectronics Sa | Controle de l'execution d'un algorithme par un circuit integre |
KR101778306B1 (ko) | 2011-03-11 | 2017-09-13 | 한양대학교 에리카산학협력단 | 시공간적 개념을 사용하는 메모리 폴트 시뮬레이션 방법 및 장치 |
EP2746952B1 (fr) * | 2012-12-18 | 2017-02-08 | Neopost Technologies | Gestion sécurisée des traces dans un dispositif de traitement du courrier |
US11099748B1 (en) * | 2018-08-08 | 2021-08-24 | United States Of America As Represented By The Administrator Of Nasa | Fault tolerant memory card |
Family Cites Families (13)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US4633039A (en) * | 1980-12-29 | 1986-12-30 | Gte Communication Systems Corp. | Master-slave microprocessor control circuit |
US4353064A (en) * | 1981-01-14 | 1982-10-05 | Honeywell Inc. | Battery operated access control card |
WO1985002698A1 (fr) * | 1983-12-12 | 1985-06-20 | Parallel Computers, Inc. | Controleur de processeur d'ordinateur |
US4598356A (en) * | 1983-12-30 | 1986-07-01 | International Business Machines Corporation | Data processing system including a main processor and a co-processor and co-processor error handling logic |
JPS6155366A (ja) * | 1984-08-27 | 1986-03-19 | Sawafuji Electric Co Ltd | 内燃機関の点火装置 |
US4614861A (en) * | 1984-11-15 | 1986-09-30 | Intellicard International, Inc. | Unitary, self-contained card verification and validation system and method |
AU568977B2 (en) * | 1985-05-10 | 1988-01-14 | Tandem Computers Inc. | Dual processor error detection system |
JPS6246483A (ja) * | 1985-08-22 | 1987-02-28 | Casio Comput Co Ltd | Icカ−ドにおけるデ−タ書込み方式 |
US4845351A (en) * | 1985-09-30 | 1989-07-04 | Casio Computer Co., Ltd. | IC card |
US4760534A (en) * | 1985-12-26 | 1988-07-26 | Pitney Bowes Inc. | Mailing system with postage value transfer and accounting capability |
JPS62242287A (ja) * | 1986-04-15 | 1987-10-22 | Nec Corp | Icカ−ド |
US4829166A (en) * | 1986-12-01 | 1989-05-09 | Froelich Ronald W | Computerized data-bearing card and reader/writer therefor |
US4859837A (en) * | 1987-03-23 | 1989-08-22 | Halpern John Wolfgang | Portable data carrier incorporating manually presettable processing modes |
-
1988
- 1988-02-08 US US07/153,391 patent/US4908502A/en not_active Expired - Lifetime
-
1989
- 1989-02-07 CA CA000590288A patent/CA1315408C/fr not_active Expired - Fee Related
- 1989-02-08 DE DE68914696T patent/DE68914696T2/de not_active Expired - Fee Related
- 1989-02-08 CH CH423/89A patent/CH679434A5/fr not_active IP Right Cessation
- 1989-02-08 FR FR898901613A patent/FR2626991B1/fr not_active Expired - Fee Related
- 1989-02-08 AU AU29723/89A patent/AU616936B2/en not_active Ceased
- 1989-02-08 GB GB8902765A patent/GB2215888B/en not_active Expired - Fee Related
- 1989-02-08 EP EP89102139A patent/EP0328062B1/fr not_active Expired - Lifetime
- 1989-02-08 JP JP1029579A patent/JP2922211B2/ja not_active Expired - Fee Related
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US8055936B2 (en) | 2008-12-31 | 2011-11-08 | Pitney Bowes Inc. | System and method for data recovery in a disabled integrated circuit |
US8060453B2 (en) | 2008-12-31 | 2011-11-15 | Pitney Bowes Inc. | System and method for funds recovery from an integrated postal security device |
Also Published As
Publication number | Publication date |
---|---|
CA1315408C (fr) | 1993-03-30 |
GB2215888B (en) | 1992-08-26 |
AU2972389A (en) | 1989-08-10 |
JPH027184A (ja) | 1990-01-11 |
AU616936B2 (en) | 1991-11-14 |
CH679434A5 (fr) | 1992-02-14 |
GB2215888A (en) | 1989-09-27 |
GB8902765D0 (en) | 1989-03-30 |
FR2626991B1 (fr) | 1992-08-28 |
EP0328062A2 (fr) | 1989-08-16 |
EP0328062A3 (fr) | 1991-09-18 |
US4908502A (en) | 1990-03-13 |
JP2922211B2 (ja) | 1999-07-19 |
DE68914696T2 (de) | 1994-09-01 |
DE68914696D1 (de) | 1994-05-26 |
FR2626991A1 (fr) | 1989-08-11 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
EP0328062B1 (fr) | Carte à puce à tolérance de défauts | |
EP0181443B1 (fr) | Micro-ordinateur monopuce | |
US5742616A (en) | System and method testing computer memories | |
US6402026B1 (en) | Smart card and method for bidirectional data transfer between a terminal and a smart card | |
US4780601A (en) | Control system for franking machines | |
US4877945A (en) | IC card having a function to exclude erroneous recording | |
US3950729A (en) | Shared memory for a fault-tolerant computer | |
US4805109A (en) | Nonvolatile memory protection arrangement for electronic postage meter system having plural nonvolatile memories | |
EP0645046A1 (fr) | Ecriture de donnees dans une memoire remanente | |
US4845632A (en) | Electonic postage meter system having arrangement for rapid storage of critical postage accounting data in plural nonvolatile memories | |
EP0173249B2 (fr) | Système de mémoire non-volatile avec possibilité d'enregistrement de données de temps réels et de baisse de puissance pour une machine à affranchir électronique | |
EP0513880A2 (fr) | Systèmes à microprocesseur pour arrangements de machine à affranchir électronique | |
CN101135984B (zh) | 硬件信息备份装置、运行信息备份及检测信息保存方法 | |
JP3667920B2 (ja) | Icカード | |
EP0222197B1 (fr) | Systèmes pour l'emmagasinage non volatil de données et systèmes de machines à affranchir | |
US4811347A (en) | Apparatus and method for monitoring memory accesses and detecting memory errors | |
CA1267237A (fr) | Dispositif de protection de memoire remanente pour systeme d'affranchissement electronique comportant plusieurs memoires remanentes | |
US4713769A (en) | Method and apparatus for locating and displaying historical information within an electronic postage meter | |
US4731748A (en) | Pocket computer with means for checking the detachable memory module before and after power interruption | |
US5109507A (en) | Electronic postage meter having redundant memory | |
US5088092A (en) | Width-expansible memory integrity structure | |
EP0356052A2 (fr) | Machine à affranchir | |
JPH03147086A (ja) | Icカード | |
EP0231452B2 (fr) | Systèmes à microprocesseur pour dispositif d'affranchissement électronique | |
JPS5850029A (ja) | 停電検出装置 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): DE |
|
PUAL | Search report despatched |
Free format text: ORIGINAL CODE: 0009013 |
|
AK | Designated contracting states |
Kind code of ref document: A3 Designated state(s): DE |
|
17P | Request for examination filed |
Effective date: 19920304 |
|
17Q | First examination report despatched |
Effective date: 19930730 |
|
GRAA | (expected) grant |
Free format text: ORIGINAL CODE: 0009210 |
|
AK | Designated contracting states |
Kind code of ref document: B1 Designated state(s): DE |
|
REF | Corresponds to: |
Ref document number: 68914696 Country of ref document: DE Date of ref document: 19940526 |
|
PLBI | Opposition filed |
Free format text: ORIGINAL CODE: 0009260 |
|
26 | Opposition filed |
Opponent name: FRANCOTYP-POSTALIA GMBH Effective date: 19950120 |
|
PLAB | Opposition data, opponent's data or that of the opponent's representative modified |
Free format text: ORIGINAL CODE: 0009299OPPO |
|
R26 | Opposition filed (corrected) |
Opponent name: FRANCOTYP-POSTALIA AKTIENGESELLSCHAFT & CO. Effective date: 19950120 |
|
PLBO | Opposition rejected |
Free format text: ORIGINAL CODE: EPIDOS REJO |
|
PLBN | Opposition rejected |
Free format text: ORIGINAL CODE: 0009273 |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: OPPOSITION REJECTED |
|
27O | Opposition rejected |
Effective date: 19970714 |
|
PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: DE Payment date: 20070330 Year of fee payment: 19 |
|
PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: DE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20080902 |